Trend analysis papers

From: dodo (ro_dodo_at_hotmail.com)
Date: 07/01/03

  • Next message: Gary Halleen: "RE: Foundry ServerIronXL Question"
    To: <focus-ids@securityfocus.com>
    Date: Tue, 1 Jul 2003 11:15:01 +0300
    
    

    Hello,

    I'm doing a research about Intrusion detection and I'm trying to make an
    analysis according to some log files (snort). Now, I'm not sure what are the
    parameters that might effect (correlate) each other.
    Moreover, I know that this problem is not a simple one due to the fact that
    my log is full with false-positive alert. I tried to find in sans reading
    room and securityfocus but there is no article about this issue.

    Any comments/reference/full answers will be most appreciated.

    Thanks a lot,

    Ido.

    -------------------------------------------------------------------------------
    The Lightning Console aggregates IDS events, correlates them with vulnerability
    info, reduces false positives with the click of a button, and distributes this
    information to hundreds of users.

    Visit Tenable Network Security at http://www.tenablesecurity.com to learn more.
    -------------------------------------------------------------------------------


  • Next message: Gary Halleen: "RE: Foundry ServerIronXL Question"

    Relevant Pages

    • Re: Strange disk usage problem
      ... > If instead of rebooting, you'll kill snort and mysql, will the problem ... log if the disk really were full. ... > any log files produces by snort/mysql? ...
      (comp.unix.bsd.freebsd.misc)
    • Re: rpc.statd attack
      ... > I saw a couple of these in my log files last night. ... > find out what the IP of these bozos is. ... I use snort 1.7 to track the alleged incoming IP numbers; ... have reported back to me that in fact they found hacked LINUX boxes ...
      (FreeBSD-Security)
    • media streams recreation
      ... i m doing some analysis on pcap based log files (obtained from snort ... I have tried to recover most of the files that i wanted ...
      (Pen-Test)